Methods and apparatus for providing one-arm node clustering using a port channel
Summary by NHIP
One-Arm Node Clustering System
The system clusters application nodes via a port channel that implements a self forward check to prevent prohibited data loops. A control link VLAN manages control data while a network interface controller allocates total available bandwidth between the VLAN and the port channel.
Claim Score by NHIP
Abstract
Methods and apparatus for providing one-arm node clustering using a port channel are provided herein. An example application node may be communicatively connected to at least one application node, and the application node may be connected to a network through a port channel. The application node may include: a link included in the port channel for accommodating the network data being communicated between the remote client and server; and a processor configured to send/receive a cluster control packet to/from the at least one application node through the link included in the port channel.

Term
6.2 yearsleft in the term
Expires 1 December 2032, including 254 days of term adjustment.
- Priority and filed
- Granted
- Today
- Expires
18 claims: 3 independent, 15 dependent
- 1Broadest claimClaim Score 36, narrow(NHIP)An application node cluster, comprising:at least two application nodes in communication over a network to provide at least one application service on network data;a port channel comprising a plurality of network ports connecting the at least two application nodes to a network stack, wherein the port channel includes a link to the network stack and receives the network data being sent or received by at least one of the application nodes through the link, and wherein the port channel is configured to operate with a self forward check implemented in the network stack, wherein the self forward check identifies data communication among the at least two application nodes connected to the port channel as a prohibited data loop and prevents the prohibited data loop;a control link virtual local area network (VLAN) connected to the network stack and managing control data for the network data transmitted/received by at least one of the application nodes, wherein said control link virtual local area network (VLAN) accommodates data communication among the at least two application nodes;a network interface controller in communication with at least one of the application nodes, said network interface controller allocating total available bandwidth for the communication between the control link virtual local area network (VLAN) and the port channel.
- 7A network stack, comprising:a port channel comprising a plurality of network ports connecting the network stack to at least two application nodes communicating over a network, wherein the port channel includes a link to the network stack, the network data being sent or received by at least one of the application nodes through the link;a switch connected to the port channel, said switch comprising a network interface controller implementing a self forward check, wherein the self forward check identifies data communication among the at least two application nodes connected to the port channel as a prohibited data loop and prevents the data communication among the at least two application nodes;a control link virtual local area network (VLAN) managing control data for the network data transmitted/received by the application nodes, wherein said control link virtual local area network (VLAN) accommodates data communication among the at least two application nodes and the network stack;and an integrated circuit comprising non-transitory computer readable memory implementing computerized software that configures the integrated circuit to encapsulate packets of the network data with MAC-in-MAC (MiM) addressing that disables the self-forward check such that the control link virtual local area network (VLAN) accommodates data communication among the at least two application nodes.
- 13A method for communication among application nodes, the method comprising:providing at least one application node in communication with at least one other application node to provide an application service on network data;configuring a port channel comprising a plurality of network ports connecting the at least one application node and the at least one other application node to a network stack, the network data being sent or received by the application nodes through the port channel;configuring the port channel with an optionally initiated self forward check preventing data communication among the at least two application nodes via the port channel;configuring a control link virtual local area network for managing control data for the network data transmitted/received by the at least one application node and the at least one other application node, wherein said control link virtual local area network accommodates data communication among the application nodes;receiving a first instance of the network data through the link included in the port channel;and forwarding the first instance of the network data through the port channel as a cluster control packet, wherein the first instance of the network data comprises a payload and a header with MAC-in-MAC (MiM) addressing that disables the self-forward check such that the control link virtual local area network (VLAN) accommodates the data communication among the application nodes.
Independent claims3
44 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION
0001This application is a continuation application of currently pending U.S. application Ser. No. 14/704,584 filed on May 5, 2015, which is a continuation of U.S. application Ser. No. 13/427,274 filed Mar. 22, 2012, issued as U.S. Pat. No. 9,025,597 on May 5, 2015, and as such, this application claims benefit of and priority to the earlier-filed applications, both of which are fully incorporated by reference herein and made a part hereof.
BACKGROUND
0002It may be desirable to provide a network application service by bundling multiple application nodes to achieve high scalability. Each application node (i.e., an appliance form factor or service module) may run an identical policy suite and maintain a coherent running state. By clustering application nodes, it may be possible to aggregate the resources of the cluster to accommodate heavier system load. For example, an application cluster including n-active nodes may achieve close-to-nX performance. The application cluster may be provided between a remote client and server. In some implementations, the application cluster may provide a network application service such as a firewall, for example. Network traffic flowing between the remote client and server may be intercepted by the application cluster and inspected by one of the application nodes before a service is performed on the network traffic. When the network application service is a firewall, the application node may enforce security rules and either forward or drop the intercepted packet, for example.
0003The application nodes may be bundled using a port channel for network traffic. In a port channel, a plurality of network ports are bundled into a group (i.e., a single logical port channel), which provides increased bandwidth and redundancy. The port channel remains operational as long as a single network port within the port channel is operational. In addition, a hashing algorithm may be used to determine which network port within the port channel should receive the packet. It is also possible to provide load-balancing among the application nodes using the hashing algorithm.
0004Many network application services require incoming and return packets for the same TCP session to be handled by the same application node. This is known as symmetric flow persistence. To ensure symmetric flow persistence, the application nodes may designate a control link VLAN for accommodating control traffic (i.e., communication among member nodes) such as packet forwarding, flow state replication, etc. In other words, the port channel may accommodate the network traffic flowing between the remote client and server and the control link VLAN may accommodate the control traffic flowing among the member nodes. When a control link VLAN is provided in addition to the port channel, each application node divides the available network resources at the network interface controller (NIC). In particular, the available bandwidth is allocated between the port channel and the control link VLAN. However, it is difficult to allocate the proper amount of bandwidth to the control link VLAN because many factors contribute to how much control traffic flows among the member nodes. If too much bandwidth is allocated to the control link VLAN, the total available bandwidth is underutilized. On the other hand, if too little bandwidth is allocated, the control link VLAN becomes saturated, which degrades the effective bandwidth of the cluster. In addition, when each application node includes a link within the port channel and a link within the control link VLAN, each application node is more susceptible to failure because failure may result from failure of either link.
SUMMARY
0005Methods and apparatus for providing one-arm node clustering using a port channel are provided herein. An example application node may be communicatively connected to at least one application node, and the application node may be connected to a network through a port channel. The application node may include: a link included in the port channel for accommodating the network data being communicated between the remote client and server; and a processor configured to send/receive a cluster control packet to/from the at least one application node through the link included in the port channel. The cluster control packet may include a payload that synchronizes flow between the application node and the at least one application node.
0006Optionally, the processor may be configured to: receive a first instance of the network data through the link included in the port channel; and forward the first instance of the network data through the link included in the port channel as the cluster control packet. For example, the first instance of the network data may be the payload.
0007In addition, the processor may be configured to: receive a second instance of the network data through the link included in the port channel; and provide the application service on the second instance of the network data.
0008Alternatively or additionally, the processor may be further configured to: generate flow state replication data; and forward the flow state replication data to the at least one application node through the link included in the port channel as the cluster control packet. For example, the flow state replication data may be the payload.
0009In some implementations, the application node may only be connected to the network through the port channel. Accordingly, the network data and the cluster control packet may be communicated over the port channel.
0010In another implementation, the processor may be configured to encapsulate the cluster control packet with MAC-in-MAC (MiM) fields. For example, the MiM fields may include a destination MAC address and a source MAC address.
0011In yet another implementation, the cluster control packet may include an outer destination MAC address field, an outer source MAC address field, a destination address field and a source address field. In addition, the destination and source address fields may be dummy addresses or original destination and source addresses of a forwarded packet.
0012One of ordinary skill in the art would understand that the above-described subject matter may also be implemented as a method, a computer process, or an article of manufacture, such as a computer-readable storage medium.
0013Other systems, methods, features and/or advantages will be or may become apparent to one with skill in the art upon examination of the following drawings and detailed description. It is intended that all such additional systems, methods, features and/or advantages be included within this description and be protected by the accompanying claims.
BRIEF DESCRIPTION OF THE DRAWINGS
0014The components in the drawings are not necessarily to scale relative to each other. Like reference numerals designate corresponding parts throughout the several views.
0015<figref idref="DRAWINGS">FIG. 1</figref> illustrates an example system for providing a network application service with a cluster of application nodes;
0016<figref idref="DRAWINGS">FIG. 2</figref> illustrates another example system for providing a network application service with a cluster of application nodes;
0017<figref idref="DRAWINGS">FIGS. 3A and 3B</figref> illustrate example logical block diagrams for providing a network application service with a cluster of application nodes;
0018<figref idref="DRAWINGS">FIG. 4</figref> illustrates an example encapsulated packet according to an implementation of the invention;
0019<figref idref="DRAWINGS">FIG. 5</figref> illustrates example operations for providing a network application service using a cluster of application nodes within the system of <figref idref="DRAWINGS">FIG. 2</figref>; and
0020<figref idref="DRAWINGS">FIG. 6</figref> illustrates an example computing device.
DETAILED DESCRIPTION
0021Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art. Methods and materials similar or equivalent to those described herein can be used in the practice or testing of the present disclosure. While implementations will be described for providing a network application service, such as a firewall, using an application cluster, it will become evident to those skilled in the art that the implementations are not limited thereto, but are applicable for providing any network application service using cluster of application nodes.
0022Referring to <figref idref="DRAWINGS">FIG. 1</figref>, an example system for providing a network application service using a cluster of application nodes is shown. The system may include a network stack <b>101</b> housing a plurality of network devices such as switches, routers, hubs, bridges, etc. In <figref idref="DRAWINGS">FIG. 1</figref>, the network stack <b>101</b> may include a switch <b>103</b>, for example. An application cluster <b>105</b> may include a plurality of application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N. Although the application cluster <b>105</b> shown in <figref idref="DRAWINGS">FIG. 1</figref> includes four application nodes, more or less than four application nodes may be included in other implementations. The application cluster <b>105</b> may be provided between a remote client and server. The remote client and server may be connected to the application cluster <b>105</b> through a network, such as a LAN, WAN or MAN, for example. The remote client and server may be connected to the network through any type of connection including, but not limited to Ethernet, Wi-Fi, WiMAX, 3G or 4G. In addition, the remote client and server and application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N may be implemented as the computing device discussed with regard to <figref idref="DRAWINGS">FIG. 6</figref>.
0023By providing the application cluster <b>105</b> between the remote client and server, one of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N may intercept network traffic flowing between the remote client and server. For example, one of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N may intercept a packet flowing between the remote client and server in order to perform an application service on the packet. The application cluster <b>105</b> (and the application service it performs), however, may be transparent to the remote client and server. In particular, the application cluster <b>105</b> may provide a network service, such as a firewall, for example. Each of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N within the application cluster <b>105</b> may run an identical security policy suite and may maintain a coherent running state as compared to the other application nodes. Alternatively, each of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N may cover a different set of security policies and act as a stand-by node to the other application nodes on the policies it does not actively perform. Accordingly, when the application cluster <b>105</b> provides a firewall as the application service, one of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N may intercept and inspect packets flowing between the remote client and server. The application node <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N may then enforce a set of security policies and either forward or drop the packets.
0024Each of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N within the application cluster <b>105</b> may be connected to the switch <b>103</b> through a port channel <b>109</b>. The port channel <b>109</b> provides a means for bundling individual interfaces into a group to provide increased bandwidth and redundancy. For example, a plurality of interfaces (or ports) of the switch <b>103</b> may be bundled into the port channel <b>109</b>, which acts as a single logical channel to which each of the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N are connected. Specifically, as shown in <figref idref="DRAWINGS">FIG. 1</figref>, links <b>113</b>A, <b>113</b>B, <b>113</b>C, <b>113</b>N may be bundled in the port channel <b>109</b>. The port channel <b>109</b> provides increased bandwidth because the bandwidth of the links may be aggregated. In addition, the port channel <b>109</b> provides increased redundancy because only one of the links <b>113</b>A, <b>113</b>B, <b>113</b>C, <b>113</b>N needs to remain operational for the port channel <b>109</b> to remain operational. The switch <b>103</b> may utilize a hashing algorithm to determine over which of the links <b>113</b>A, <b>113</b>B, <b>113</b>C, <b>113</b>N to send network data. In addition, it may be possible to provide load-balancing among the links <b>113</b>A, <b>113</b>B, <b>113</b>C, <b>113</b>N using the hashing algorithm.
0025The application service provided by the application cluster <b>105</b> may require that incoming and return network traffic be handled by the same application node <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N, which is known as symmetric flow persistence. In particular, the application service may require that the incoming and return packets for the same TCP session be handled by the same application node <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N. For example, when the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N are connected to the switch <b>103</b> through the port channel <b>109</b>, an incoming packet flowing between the remote client and server may be handled by application node <b>107</b>A. Application node <b>107</b>A may perform the network service on the incoming packet and subsequently forward the incoming packet to its destination over the port channel <b>109</b>. In addition, application node <b>107</b>A may save the TCP flow in a flow table, which may be synchronized with the other application nodes of the application cluster <b>105</b>. Thereafter, a return packet flowing between the remote client and server, which is part of the same TCP session as the incoming packet, may be received by application node <b>107</b>B over the port channel <b>109</b> (i.e., through link <b>113</b>B). In order to maintain symmetric flow persistence, the return packet may preferably be forwarded from application node <b>107</b>B to application node <b>107</b>A.
0026However, it may not be possible to forward the return packet from application node <b>107</b>B to application node <b>107</b>A using the port channel <b>109</b>. In particular, the switch <b>103</b> prevents data communication from flowing among application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N connected to the port channel <b>109</b> because such data communication is considered a loop. Therefore, the self forwarding check or the self forward check, which may be implemented by an ASIC of the network controller of the switch <b>103</b>, may cause the return packet to be dropped if the return packet is forwarded over the port channel <b>109</b>. Accordingly, in order to provide symmetric flow persistence, a control link VLAN <b>111</b> may be provided to accommodate data communication among application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N including data regarding packet forwarding, packet duplication, flow state replication and any other data communicated among the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N. As shown in <figref idref="DRAWINGS">FIG. 1</figref>, links <b>115</b>A, <b>115</b>B, <b>115</b>C, <b>115</b>N are included in the control link VLAN <b>111</b>. Application node <b>107</b>B may therefore forward the return packet to application node <b>107</b>A using the control link VLAN <b>111</b> so that application node <b>107</b>A may handle both the incoming and return packets from the same TCP session.
0027When a control link VLAN <b>111</b> is provided in addition to the port channel <b>109</b>, the network resources must be allocated between the control link VLAN <b>111</b> and the port channel <b>109</b>. For example, the total available bandwidth may be allocated between the control link VLAN <b>111</b> and the port channel <b>109</b> at the NIC of the application node <b>107</b>A, <b>107</b>B, <b>107</b>C or <b>107</b>N. However, as discussed above, it may be difficult to properly allocate the total available bandwidth because the bandwidth required to accommodate the control traffic among the application nodes <b>107</b>A, <b>107</b>B, <b>107</b>C, <b>107</b>N depends on many factors, and improper allocation may lead to underutilization of the total bandwidth or degradation of the effective bandwidth.
0028Referring to <figref idref="DRAWINGS">FIG. 2</figref>, another example system for providing a network application service using a cluster of application nodes is shown. The system may include a network stack <b>201</b> housing a plurality of network devices such as switches, routers, hubs, bridges, etc. For example, the network stack <b>201</b> may include a switch <b>203</b>. In addition, an application cluster <b>205</b> may be provided between a remote client and server. The application cluster <b>205</b> may provide a network application service on the network communication flowing between the remote client and server. Additionally, the application cluster <b>205</b> may include application nodes <b>207</b>A, <b>207</b>B, <b>207</b>C, <b>207</b>N. Although the application cluster <b>205</b> shown in <figref idref="DRAWINGS">FIG. 2</figref> includes four application nodes, more or less than four application nodes may be included in other implementations. The remote client and server may be connected to the application cluster <b>205</b> through a network, such as a LAN, WAN or MAN, for example. The remote client and server may be connected to the network through any type of connection including, but not limited to Ethernet, Wi-Fi, WiMAX, 3G or 4G. In addition, the remote client and server and application nodes <b>207</b>A, <b>207</b>B, <b>207</b>C, <b>207</b>N may be implemented as the computing device discussed with regard to <figref idref="DRAWINGS">FIG. 6</figref>.
0029The system shown in <figref idref="DRAWINGS">FIG. 2</figref> functions similarly to the system shown in <figref idref="DRAWINGS">FIG. 1</figref> in many aspects. In contrast to the system shown in <figref idref="DRAWINGS">FIG. 1</figref>, however, the application nodes <b>207</b>A, <b>207</b>B, <b>207</b>C, <b>207</b>N shown in <figref idref="DRAWINGS">FIG. 2</figref> are only connected to the switch <b>203</b> through the port channel <b>209</b>. The port channel <b>209</b> includes links <b>213</b>A, <b>213</b>B, <b>213</b>C, <b>213</b>N. Accordingly, the system shown in <figref idref="DRAWINGS">FIG. 2</figref> does not include a control link VLAN. In other words, each of the application nodes <b>207</b>A, <b>207</b>B, <b>207</b>C, <b>207</b>N functions as a one-arm node because each of the nodes is only connected to the network through the port channel <b>209</b>. In addition, the port channel <b>209</b> accommodates the network traffic flowing between the remote client and server and the control traffic flowing among the application nodes <b>207</b>A, <b>207</b>B, <b>207</b>C, <b>207</b>N.
0030The system shown in <figref idref="DRAWINGS">FIG. 2</figref> may also require symmetric flow persistence such that incoming and return packets for the same TCP session are handled by the same application node <b>207</b>A, <b>207</b>B, <b>207</b>C or <b>207</b>N. For example, an incoming packet flowing between the remote client and server may be intercepted, inspected and serviced by application node <b>207</b>A. After providing the application service, application node <b>207</b>A may save TCP flows in a flow table and forward the incoming packet to its destination. Thereafter, the return packet, which is part of the same TCP session as the incoming packet, may be received by application node <b>207</b>B. In order to provide symmetric flow persistence, application node <b>207</b>B may preferably forward the return packet to application node <b>207</b>A after determining that the incoming packet from the same TCP session was handled by application node <b>207</b>A. Unlike the system shown in <figref idref="DRAWINGS">FIG. 1</figref>, the port channel <b>209</b> of the system shown in <figref idref="DRAWINGS">FIG. 2</figref> may accommodate the network traffic flowing between the remote client and server as well as control traffic flowing among the application nodes <b>207</b>A, <b>207</b>B, <b>207</b>C, <b>207</b>N.
0031By providing a port channel that accommodates both the network traffic and the control traffic, it is possible to more efficiently utilize available bandwidth and increase reliability. For example, in order to prevent the control link VLAN from becoming saturated, excess bandwidth may be allocated to the control link VLAN, which results in underutilization of the total available bandwidth. However, when the port channel accommodates both the network traffic and the control traffic, the total available bandwidth is allocated to the port channel alone. In addition, each appliance node can join both ports into the same port-channel. If one port fails, the appliance still have both data and control connectivity. Otherwise the appliance would lose either data or control connectivity resulting in a useless node.
0032Referring to <figref idref="DRAWINGS">FIGS. 3A and 3B</figref>, example logical block diagrams for providing an application service using a cluster of application nodes are shown. As shown in <figref idref="DRAWINGS">FIG. 3A</figref>, the client <b>301</b> and the server <b>303</b> may be L2/L3 adjacent. In addition, an application cluster <b>307</b> may be provided between the client <b>301</b> and the server <b>303</b>. The application cluster <b>307</b> may include Node <b>1</b>, Node <b>2</b> and Node N, for example. Although three nodes are shown in the application cluster <b>307</b>, it may be possible to provide more or less than three nodes. As discussed above, an application service may be provided on the network traffic (i.e., packets) flowing between the client <b>301</b> and the server <b>303</b>. For example, one of the nodes of the application cluster <b>307</b> may intercept, inspect and service a packet flowing between the client <b>301</b> and the server <b>303</b>. This is represented by reference numeral <b>302</b>A shown in <figref idref="DRAWINGS">FIG. 3A</figref>. As discussed above with regard to <figref idref="DRAWINGS">FIGS. 1 and 2</figref>, one of the nodes of the application cluster <b>307</b> receives the packet through the port channel <b>305</b>. The port channel <b>305</b> allows the links to each of the nodes of the application cluster <b>307</b> to be bundled into a single logical channel. In addition, a control link VLAN <b>309</b> is provided to accommodate control traffic flowing among the nodes of the application cluster <b>307</b>. For example, the control link VLAN <b>309</b> may accommodate a packet forwarded between Node <b>1</b> and Node <b>2</b> in order to provide symmetric flow persistence. Alternatively or additionally, the control link VLAN <b>309</b> may accommodate any data communication flowing among the nodes of the application cluster <b>307</b>. This is represented by reference numeral <b>302</b>B shown in <figref idref="DRAWINGS">FIG. 3A</figref>. As discussed above, the control link VLAN <b>309</b> is provided because the port channel <b>305</b> may not accommodate data communication flowing among the nodes of the application cluster <b>307</b>. Specifically, the self forwarding check or the self forward check of the network device on which the port channel is configured may prevent data communication among the ports within the port channel. In some implementations, the self forwarding check or the self forward check may be implemented by an ASIC of the network device.
0033The example block diagram for providing an application service using a cluster of application nodes shown in <figref idref="DRAWINGS">FIG. 3B</figref> is similar to the example block diagram shown in FIG. <b>3</b>A. Therefore, the features having similar reference numerals will not be discussed in detail with regard to <figref idref="DRAWINGS">FIG. 3B</figref>. Unlike the block diagram shown in <figref idref="DRAWINGS">FIG. 3A</figref>, the block diagram shown in <figref idref="DRAWINGS">FIG. 3B</figref> includes a port channel <b>305</b> that accommodates the network traffic flowing between the client <b>301</b> in the server <b>303</b> as well as the control traffic flowing among the nodes of the application cluster <b>307</b>. This is represented by reference numerals <b>302</b>A and <b>302</b>B shown in <figref idref="DRAWINGS">FIG. 3B</figref>.
0034Referring to <figref idref="DRAWINGS">FIG. 4</figref>, an example encapsulated packet according to an implementation of the invention is shown. As discussed above, the self forwarding check (or the self forward check) in the port channel prevents a member port from sending a packet to another member port on the port channel. For example, an ASIC of the network device on which the port channel is configured may implement the self-forwarding check. Thus, in order to send control traffic among member ports of the port channel, the self forwarding check may be bypassed. One example way to bypass the self forwarding check is by using MAC-in-MAC (MiM) addressing because the ASIC is configured to be disabled for MiM addressing. <figref idref="DRAWINGS">FIG. 4</figref> illustrates an example encapsulated packet <b>400</b>. The packet payload <b>410</b> may be any data to be communicated among the member ports of the port channel. For example, the packet payload <b>410</b> may include flow synchronization data. The encapsulated packet <b>400</b> may have an outer address including the outer destination address, which may be the destination MAC address of the destination application node, and the outer source address, which may be the source MAC address of the source application node, for example. In addition, the encapsulated packet <b>400</b> may have an inner address including the destination address and the source address. The inner address may be provided with dummy addresses if the payload is an application's meta data, such as flow states, for example. However, if the payload is the original packet payload, the inner address may retain the original packet's source and destination addresses. Accordingly, in order to encapsulate the packet, the application nodes may be configured to encapsulate the payload packet <b>410</b> with the outer destination address and the outer source address. For example, the NIC of the application node may be configured to encapsulate the packets. Because the self forwarding check is disabled for MiM addressing, the payload packet <b>410</b> may be delivered from one node to another node within the port channel.
0035Referring to <figref idref="DRAWINGS">FIG. 5</figref>, example operations for providing a network application service using a cluster of application nodes is shown. At <b>502</b>, network data may be received at an application node. The network data may include a packet flowing between a remote client and server, for example. In addition, the application node may be one of a plurality of application nodes in an application cluster. The application cluster may provide a network application service on the network data. The network data may be received at the application node over a link in a port channel. As discussed above, the port channel may include a plurality of network ports (i.e., links) bundled into a single logical channel. Accordingly, the port channel may include the links to each of the application nodes.
0036An <b>504</b>, a determination is made by the application node as to whether the network data should be serviced by the application node. For example, in order to provide symmetric flow persistence, an application service may require that incoming and return packets from the same TCP session be handled by the same application node. However, when using a port channel, a return packet may be received by an application node that did not handle the incoming packet from the same TCP session. Accordingly, the return packet may preferably be forwarded to the application node that handled the incoming packet. This determination may be made by referring to a flow table, for example.
0037If the application node should service the network data, the application node may perform the application service on the network data at <b>506</b>. Thereafter, at <b>508</b>, the network data may be sent to its destination over the port channel. Optionally, the application node may also save the TCP flow to a flow table. If the application node should not service the network data, the application node may encapsulate the network data at <b>510</b>. For example, when the network data is a return packet related to a TCP session that was handled by a different application node, the network data may preferably be forwarded to the application node that handled the incoming packet. The network data may be encapsulated using MiM addressing (i.e., provided with an outer destination MAC address and an outer source MAC address), for example. At <b>512</b>, the application node may send the encapsulated over the port channel. Because the network data is encapsulated using MiM addressing, the encapsulated network data may bypass the self forwarding check.
0038The operations of <figref idref="DRAWINGS">FIG. 5</figref> are related to forwarding packets received by one member node to another member node within the application cluster over the port channel. However, one of ordinary skill in the art would understand that the application node may be configured to encapsulate and forward any data over the port channel to another member node within the application cluster. For example, the application node may generate flow replication data, encapsulate the flow replication data and forward the flow replication data over the port channel to another member node. In other words, the encapsulated data may be cluster control data as well as network data.
0039Referring to <figref idref="DRAWINGS">FIG. 6</figref>, an example computing device is illustrated. The client, server and/or application node discussed above may be computing devices, such as computing device <b>600</b> shown in <figref idref="DRAWINGS">FIG. 6</figref>. In its most basic configuration, computing device <b>600</b> typically includes at least one processing unit <b>606</b> and memory <b>604</b>. Depending on the exact configuration and type of computing device, memory <b>604</b> may be volatile (such as random access memory (RAM)), non-volatile (such as read-only memory (ROM), flash memory, etc.), or some combination of the two. This most basic configuration is illustrated in <figref idref="DRAWINGS">FIG. 6</figref> by dashed line <b>602</b>. The processing unit may be a standard programmable processor that performs arithmetic and logic operations necessary for operation of the computing device <b>600</b>.
0040The processing unit <b>606</b> may be configured to execute program code encoded in tangible, computer-readable media. For example, the processing unit <b>606</b> may execute program code stored in the system memory <b>604</b>.
0041Computing device <b>600</b> may have additional features/functionality. For example, computing device <b>600</b> may include additional storage such as removable storage <b>608</b> and non-removable storage <b>610</b> including, but not limited to, magnetic or optical disks or tapes. Computing device <b>600</b> may also contain a network interface controller <b>616</b> that allow the device to communicate with other devices. In some implementations, the network interface controller <b>616</b> may include its own processor and memory. The processor of the network interface controller may be a standard programmable processor or a processor configured to implement a specific function. Computing device <b>600</b> may also have input device(s) <b>614</b> such as a keyboard, mouse, touch screen, etc. Output device(s) <b>614</b> such as a display, speakers, printer, etc. may also be included. All these devices are well known in the art and need not be discussed at length here.
0042Computing device <b>600</b> typically includes a variety of computer readable media. Computer readable media can be any available media that can be accessed by device <b>600</b> and includes both volatile and non-volatile media, removable and non-removable media. Computer storage media include volatile and non-volatile, and removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. System memory <b>604</b>, removable storage <b>608</b>, and non-removable storage <b>610</b> are all examples of computer storage media. Computer storage media include, but are not limited to, RAM, ROM, electrically erasable program read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by computing device <b>600</b>. Any such computer storage media may be part of computing device <b>600</b>.
0043It should be understood that the various techniques described herein may be implemented in connection with hardware, firmware or software or, where appropriate, with a combination thereof. Thus, the methods and apparatuses of the presently disclosed subject matter, or certain aspects or portions thereof, may take the form of program code (i.e., instructions) embodied in tangible media, such as floppy diskettes, CD-ROMs, hard drives, or any other machine-readable storage medium wherein, when the program code is loaded into and executed by a machine, such as a computing device, the machine becomes an apparatus for practicing the presently disclosed subject matter. In the case of program code execution on programmable computers, the computing device generally includes a processor, a storage medium readable by the processor (including volatile and non-volatile memory and/or storage elements), at least one input device, and at least one output device. One or more programs may implement or utilize the processes described in connection with the presently disclosed subject matter, e.g., through the use of an application programming interface (API), reusable controls, or the like. Such programs may be implemented in a high level procedural or object-oriented programming language to communicate with a computer system. However, the program(s) can be implemented in assembly or machine language, if desired. In any case, the language may be a compiled or interpreted language and it may be combined with hardware implementations.
0044Although of the subject matter has been described in language specific to structural features and/or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Contents5
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2004133693A1 | Cites | United States of America | Search report |
| US2006143300A1 | Cites | United States of America | Applicant |
| US2007171904A1 | Cites | United States of America | Search report |
| US2008089247A1 | Cites | United States of America | Applicant |
| US2009141731A1 | Cites | United States of America | Applicant |
| US2009185571A1 | Cites | United States of America | Search report |
| US2011134925A1 | Cites | United States of America | Applicant |
| US2012027017A1 | Cites | United States of America | Applicant |
| US2012106339A1 | Cites | United States of America | Applicant |
| US2012257631A1 | Cites | United States of America | Applicant |
| US2013107709A1 | Cites | United States of America | Applicant |
| US6208644B1 | Cites | United States of America | Applicant |
| US6331984B1 | Cites | United States of America | Applicant |
| US6910149B2 | Cites | United States of America | Applicant |
| US7099337B2 | Cites | United States of America | Applicant |
| US7146452B2 | Cites | United States of America | Applicant |
| US7580417B2 | Cites | United States of America | Applicant |
| US7623455B2 | Cites | United States of America | Applicant |
| US7756029B2 | Cites | United States of America | Applicant |
| US7912091B1 | Cites | United States of America | Applicant |
| US8208370B1 | Cites | United States of America | Applicant |
| US8335236B2 | Cites | United States of America | Applicant |
| US8804733B1 | Cites | United States of America | Applicant |
| US9246702B1 | Cites | United States of America | Applicant |
| US20040133693A1 | Cites | United States of America | Search report |
| US20060143300A1 | Cites | United States of America | Applicant |
| US20070171904A1 | Cites | United States of America | Search report |
| US20080089247A1 | Cites | United States of America | Applicant |
| US20090141731A1 | Cites | United States of America | Applicant |
| US20090185571A1 | Cites | United States of America | Search report |
| US20110134925A1 | Cites | United States of America | Applicant |
| US20120027017A1 | Cites | United States of America | Applicant |
| US20120106339A1 | Cites | United States of America | Applicant |
| US20120257631A1 | Cites | United States of America | Applicant |
| US20130107709A1 | Cites | United States of America | Applicant |
6 members in 1 office
Members6
| Document | Office | Kind | |
|---|---|---|---|
| US2013250952A1 | United States of America | A1 | |
| US9025597B2 | United States of America | B2 | |
| US2015237170A1 | United States of America | A1 | |
| US9560168B2 | United States of America | B2 | |
| US2017111479A1 | United States of America | A1 | |
| US10135951B2This record | United States of America | B2 |
46 transactions on the USPTO file
Allowed after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Paralegal or electronic terminal disclaimer approvedP574 | P574 | |
| Response after Non-Final ActionA... | A... | |
| Terminal Disclaimer FiledDIST | DIST | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Application Dispatched from OIPEOIPE | OIPE | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Cleared by OIPE CSRL194 | L194 | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| PTO/SB/69-Authorize EPO Access to Search ResultsSREXR141 | SREXR141 | |
| Applicants have given acceptable permission for participating foreignAPPERMS | APPERMS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 10135951
- Application
- 15392088
Titles
- English
- Methods and apparatus for providing one-arm node clustering using a port channel
Patent term adjustment
- A delay
- +254 daysthe office missed an examination deadline
- Net adjustment
- 254 days
Classification
- CPC, 7
- H04L67/42
- H04L67/1027
- H04L7/0008
- H04L67/01
- H04L12/4641
- H04L45/38
- H04L67/10
- IPC, 6
- H04W4 00
- H04L29 06
- H04L29 08
- H04L7 00
- H04L12 721
- H04L12 46
- USPC, 1
- 709230000